MongoDB
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 199 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 1, 2013 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Server crash via aggregation pipeline expression with compound wildcard index specification
Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META
Transaction Command Insufficient Input Validation Leading to Process Termination
Find command with $meta sort can lead to crash
MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
libmongocrypt Improper Input Validation Leading to Process Termination
MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service
MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination
Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure
tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket
Monitor MongoDB in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.